Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-30801
HistoryOct 10, 2023 - 2:15 p.m.

Default credentials

2023-10-1014:15:00
PRIOn knowledge base
www.prio-n.com
196
qbittorrent
default credentials
remote attacker
web user interface
remote execution
march 2023

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.6%

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the “external program” feature in the web user interface. This was reportedly exploited in the wild in March 2023.

CPENameOperatorVersion
qbittorrentle4.5.5

9.7 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.6%